Protected Pre-Association Station Identification for Consistent WLAN Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing use of randomized MAC addresses in wireless devices poses challenges for WLAN infrastructure, leading to a perceived loss of utility as users are forced to log in frequently due to unrecognized stations, and existing systems fail to balance privacy with the ability to track and provide features like parental controls.

Innovation Solution

An access point requests a unique identifier from a station before association, establishes a secure connection, and receives a unique identifier response, which can be different from the MAC address, allowing for personalized features and policies based on the response.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If randomized MAC addresses are used for privacy protection, then user privacy is improved, but the ability to consistently identify stations across associations deteriorates

Engineering Contradiction:
Improveprivacy trackingVSAvoidstation identification consistency
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent segments the identification system into two parts: randomized MAC addresses for general communication and protected pre-associated station identifiers for consistent identification. This allows the system to use different identifiers for different purposes, maintaining both privacy and reliable identification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces protected pre-associated station identifiers as an intermediary mechanism between the station and access point. These identifiers are exchanged through a protected pre-association mechanism, serving as a mediator that enables consistent identification without exposing the randomized MAC addresses.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If randomized MAC addresses are used, then privacy is improved, but user convenience deteriorates due to frequent re-login requirements

Engineering Contradiction:
Improveprivacy trackingVSAvoidlogin frequency
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements preliminary action by establishing protected pre-association between stations and access points before actual network connection. During this pre-association phase, identifiers are exchanged and stored, enabling automatic recognition and eliminating the need for frequent re-logins when the station reconnects.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If unique identifiers are exchanged after association, then identification accuracy is improved, but security deteriorates due to potential interception

Engineering Contradiction:
Improveidentifier accuracyVSAvoidsecurity risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent performs the identifier exchange action preliminarily, before the formal association process. By establishing the protected pre-association channel first, the identifiers are exchanged in a secure environment before any potential security risks of post-association exchange arise.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses a protected pre-association mechanism as an intermediary channel for identifier exchange. This intermediary channel provides security protections that prevent interception and unauthorized access, ensuring secure transmission of unique identifiers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4388764B1Protected pre-association station identification
Publication Date: 2025.07.02 RUCKUS IP HOLDINGS LLC
  • EP4388764B1 patent drawingFigure 1
  • EP4388764B1 patent drawingFigure 2A~2B
  • EP4388764B1 patent drawingFigure 3A~3B

AI summary

Methods, systems, and computer readable media can be operable to facilitate an exchange of messages between an access point and a station, wherein the access point requests a unique identifier from the station. The station initiates a secure connection with the access point prior to associating with the access point. The station may either respond with a message declining to provide a unique identifier or respond with a message including a unique identifier to be used by the access point for the station via the secure connection. The response from the station may include additional limitations on the use of the unique identifier by the access point. The access point may enforce different policies against the station depending upon how the station responds to the unique identifier request.